Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add osouthgate/agent-plus-skills --skill supabase-remotegit clone --depth 1 https://github.com/osouthgate/agent-plus-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/osouthgate/agent-plus-skills/supabase-remote)<a href="https://agentmods.dev/skills/osouthgate/agent-plus-skills/supabase-remote"><img src="https://agentmods.dev/badge/skills/osouthgate/agent-plus-skills/supabase-remote/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/osouthgate/agent-plus-skills/supabase-remote"><img src="https://agentmods.dev/badge/skills/osouthgate/agent-plus-skills/supabase-remote.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00072 | $0.02948 |
| Opus 5 | $0.00036 | $0.01474 |
| Sonnet 5 | $0.00014 | $0.00590 |
| Haiku 4.5 | $0.00007 | $0.00295 |
Grade A, and why
supabase-remote scanned grade A with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reads agent configuration directorieslowAgent snooping
.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.
- **`SUPABASE_ACCESS_TOKEN is not set`**: Create a token at <https://supabase.com/dashboard/account/tokens> and drop it in `$CWD/.env` (project) or `~/.claude/settings.json` (global). Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
**This wrapper's scope is deliberately narrow:** projects list/resolve/current, SQL execution (file + inline with write-guard), RLS audit, and TypeScript gen-types. Anything outside that set is unwrapped on purpose. If t How it starts
The opening of the file, as written. The whole thing — 213 lines — stays where its author put it; the contents beside it link to each section on GitHub.
supabase-remote
Stdlib-only Python 3 CLI wrapping the Supabase Management API + the local supabase CLI. One file, no pip installs. Lives at ${CLAUDE_SKILL_DIR}/../../bin/supabase-remote; the plugin auto-adds bin/ to PATH.
Generic Supabase ops only. Domain-specific helpers (member lookups, custom comms tails, app-specific onboarding queries) belong in the consuming project's own repo and should shell out to sql-inline here for the SQL execution.
When to reach for this
- User wants to apply a SQL file to a Supabase project and confirm it worked.
- User wants to check RLS coverage before shipping.
- User wants to regenerate the TypeScript types file from the live schema.
- User asks "which project am I linked to" / "list my Supabase projects".
- User wants a one-shot read query against the linked project.
Do NOT use for auth user management, storage buckets, or edge function deploys — out of scope. For those, use the supabase CLI directly or the dashboard.
When NOT to use this — fall back to supabase CLI or Management API directly
This wrapper's scope is deliberately narrow: projects list/resolve/current, SQL execution (file + inline with write-guard), RLS audit, and TypeScript gen-types. Anything outside that set is unwrapped on purpose. If the user's request obviously needs a capability this tool doesn't expose, skip supabase-remote and reach for the supabase CLI or curl https://api.supabase.com/v1/... directly — both are already authed on their machine via SUPABASE_ACCESS_TOKEN.
Specific cases where you should use supabase ... (or curl against the Management API) directly, not supabase-remote:
- Auth user management — creating, inviting, banning, deleting users, resetting passwords, managing MFA factors. →
curl https://api.supabase.com/v1/projects/<ref>/auth/usersor the GoTrue admin API. - Storage buckets and objects — creating buckets, setting policies, uploading/downloading files, signed URLs. →
supabase storagesubcommands or the Storage REST API. - Edge function deploys and invocation —
deploy,serve,invoke, managing function secrets. →supabase functions deploy <name>/supabase functions invoke. - Database migrations /
db push/ schema diff — real migration workflows belong insupabase/migrations/and should go throughsupabase db push,supabase db diff, orsupabase migration new.sql <file>here is for seeds and one-offs, not replicable schema changes. - Project provisioning, pausing, restoring, or branch management — creating projects, pausing/restoring, managing preview branches. →
POST /v1/projects,POST /v1/projects/<ref>/pause, or the dashboard. - Vault/secrets, realtime config, network restrictions, custom domains — anything in Management API areas this CLI doesn't model. →
curl https://api.supabase.com/v1/projects/<ref>/...withAuthorization: Bearer $SUPABASE_ACCESS_TOKEN.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 213 lines · 72 tokens per session scan A b37a4a10db28
supabase-remote is a skill published in the GitHub repository osouthgate/agent-plus-skills (2 stars, last pushed 4mo ago), licensed MIT. It adds 72 tokens to every session and 2,948 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 2 findings (reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
postgres-database-migration
Use this skill for planning, testing, and safely executing PostgreSQL schema migrations — especially when working with production data or shared databases. Trigger when user asks to: Test a schema migration before applying it to production Add, remove, or rename columns safely on a live table Change a column's data…
setup-timescaledb-hypertables
Use this skill when creating database schemas or tables for Timescale, TimescaleDB, TigerData, or Tiger Cloud, especially for time-series, IoT, metrics, events, or log data. Use this to improve the performance of any insert-heavy table. Trigger when user asks to: Create or design SQL schemas/tables AND…
design-postgis-tables
Comprehensive PostGIS spatial table design reference covering geometry types, coordinate systems, spatial indexing, and performance patterns for location-based applications.
migrate-postgres-tables-to-hypertables
Use this skill to migrate identified PostgreSQL tables to Timescale/TimescaleDB hypertables with optimal configuration and validation. Trigger when user asks to: Migrate or convert PostgreSQL tables to hypertables Execute hypertable migration with minimal downtime Plan blue-green migration for large tables Validate…
pgvector-semantic-search
Use this skill for setting up vector similarity search with pgvector for AI/ML embeddings, RAG applications, or semantic search. Trigger when user asks to: Store or search vector embeddings in PostgreSQL Set up semantic search, similarity search, or nearest neighbor search Create HNSW or IVFFlat indexes for vectors…
find-hypertable-candidates
Use this skill to analyze an existing PostgreSQL database and identify which tables should be converted to Timescale/TimescaleDB hypertables. Trigger when user asks to: Analyze database tables for hypertable conversion potential Identify time-series or event tables in an existing schema Evaluate if a table would…